Path traversal vulnerability in GUI

Summary

A relative path traversal vulnerability [CWE-23] in FortiRecorder may allow a privileged attacker to read files from the underlying filesystem via crafted HTTP or HTTPs requests.

Version Affected Solution
FortiRecorder 7.2 7.2.0 through 7.2.1 Upgrade to 7.2.2 or above
FortiRecorder 7.0 7.0.0 through 7.0.4 Upgrade to 7.0.5 or above
FortiRecorder 6.4 6.4 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Théo Leleu of Fortinet Product Security team.

Timeline

2025-01-14: Initial publication